I have created two groups for my Anyconnect clients. I am using NT Domain authentication, but I want to know if it is possible to force an Anyconnect group to a user thats part of a certain OU in AD? For instance the IT group would get a group called IT and have more access than others for the other group called Public. All my IT users are in an OU, so when they authticate with their creds Anyconnect would know they belong to the IT group.